All 66 CVE vulnerabilities found in openssl_encrypt, with AI-generated Chinese analysis, references, and POCs.
This page aggregates vulnerability data for openssl_encrypt, a function within the OpenSSL cryptography library, categorized under the weakness type of Cryptographic Issues. The collection comprises security flaws reported in the openssl_encrypt function and related components, covering disclosures from 2005 to the present year. Readers can utilize this index to track specific advisories issued by the vendor, analyze the prevalence and evolution of cryptographic implementation errors, and review the complete vulnerability history associated with this cryptographic primitive. The data supports security audits and risk assessment by providing a consolidated view of past weaknesses, including improper key handling, predictable random number generation, and insufficient algorithm strength. By examining the timeline and severity scores, organizations can identify recurring patterns in implementation failures and assess the long-term stability of their cryptographic infrastructure. This resource serves as a technical reference for developers and security professionals seeking to understand historical failure points in OpenSSL encryption functions, enabling better-informed decisions regarding library updates, code refactoring, and the adoption of modern cryptographic standards to mitigate known and emerging threats.
Vendor: jahlives
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-74876 | openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption CWE-347 | 9.8 | Critical | 2026-08-17 |
| CVE-2026-74874 | openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection CWE-338 | 7.5 | High | 2026-08-17 |
| CVE-2026-74873 | openssl_encrypt before 1.4.0 Password Exposure via CLI Argument CWE-214 | 5.5 | Medium | 2026-08-17 |
| CVE-2026-74872 | openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool CWE-426 | 9.8 | Critical | 2026-08-17 |
| CVE-2026-74871 | openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR CWE-916 | 6.2 | Medium | 2026-08-17 |
| CVE-2026-74870 | openssl_encrypt before 1.4.8 Hardware Pepper Information Disclosure CWE-532 | 3.3 | Low | 2026-08-17 |
All 66 known CVE vulnerabilities affecting openssl_encrypt with full Chinese analysis, references, and POCs where available.